Information Security & Data Officer @ Buildwise
AM.S04368
Function
Buildwise aims to further professionalize and innovate within the construction sector, with the development of new digital activities—such as its own AI platform—at the center of this ambition. In this context, the overarching goal of the organization is to create a meaningful and future-proof working environment that has a positive impact on both the sector and the planet. To realize these ambitions safely and responsibly, it is essential for the organization to raise its information security to a higher level of maturity.
Within this framework, the fundamental objective of the Information & Data Security Officer (IDSO) is to develop and lead an information security strategy that ensures the confidentiality, integrity, and availability of information. The IDSO acts as a strategic guardian who ensures that security objectives are fully aligned with the organization’s business strategy and with applicable regulations, such as GDPR and NIS2.
The essence of the role lies in creating a secure foundation on which the organization can build its innovative projects without exposing itself to unacceptable risks. In doing so, the IDSO’s mission is to embed a strong and sustainable culture of information and data security throughout the entire organization, finding the right balance between minimizing risks and supporting business initiatives. Ultimately, the role aims to help transform Buildwise into an organization with mature risk management and a robust governance framework for information security.
Tasks and responsibilities
The tasks and responsibilities of the IDSO at Buildwise are broad and range from strategic policy development to the practical implementation of security measures. The role is divided into several key areas:
Strategy, policy, and compliance
Strategic roadmap:
Developing and monitoring the cybersecurity strategy and roadmap, fully aligned with Buildwise’s organizational objectives.
ISMS management:
Setting up and maintaining the Information Security Management System (ISMS), including all policies and procedures.
GDPR responsibility:
Acting as the central point of contact for GDPR, overseeing compliance within the organization and supporting privacy-by-design principles.
Regulatory compliance:
Ensuring that all processes comply with relevant laws and regulations, particularly the NIS2 directive.
Reporting:
Reporting on maturity levels, risks, and KPIs to the Executive Committee (ExCom) and relevant governance bodies.
Risk management and security operations
Risk analyses:
Regularly performing and following up on risk assessments according to standards such as ISO 27001 or CyFun.
IT security best practices:
Helping define best practices for identity and access management, network and cloud security, patch management, and backup procedures.
Vendor management:
Conducting security screenings of suppliers and monitoring security clauses in contracts.
Implementation:
Implementing and maintaining security measures for both on-premises and cloud environments.
Incidents, continuity, and culture
Continuity planning:
Coordinating the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP), including organizing testing cycles.
Incident response:
Developing and testing an Incident Response Plan, including managing notification obligations under GDPR and NIS2.
Awareness:
Organizing security awareness campaigns, such as phishing simulations and training sessions, and measuring their impact within the organization.
Culture building:
Embedding a strong security culture through leadership by example and active communication with all teams.
Profile
Education level and background:
You hold a Master’s or Bachelor’s degree in Computer Science, or have equivalent experience.
Relevant work experience:
You have 7 to 10 years of experience in information security or IT risk, with proven success in establishing an ISMS, incident response, and compliance frameworks. Certifications such as CISSP, CISM, or ISO 27001 are a strong plus.
Expertise in standards and legislation:
You have solid knowledge of NIS2, ISO 27001, the Belgian CyFun framework, and GDPR.
Technical insight:
You have a strong understanding of cloud and on-premise security, networks, and IAM; experience with Microsoft 365 security is an advantage.
Communication skills:
You can clearly explain complex technical concepts to both technical colleagues and non-technical stakeholders, including the Executive Committee (ExCom).
Personal mindset:
You are autonomous and proactive, while also being a team player who focuses on solutions rather than only identifying obstacles.
Offer
Impact on innovation:
You will have the opportunity to directly contribute to the security of groundbreaking projects for the construction sector, such as the development of an in-house AI platform.
Strategic autonomy:
As the first person in this new role, you will build the function from the ground up and act as an independent business partner, reporting directly on maturity and risks to the Executive Committee (ExCom).
Challenging scope of work:
You will find a unique balance between defining long-term strategy and hands-on execution within a complex environment of fragmented data and applications.
Competitive salary package:
The offer includes a competitive gross salary in line with your expertise and experience, as well as fringe benefits such as meal vouchers and a net expense allowance.
Modern mobility and flexibility:
You will have access to a 100% electric company car (or a mobility budget) and benefit from flexible working hours and a remote work policy to support an optimal work–life balance.
Meaningful work environment:
Buildwise offers an open and diverse workplace where well-being is central and where you contribute to a sector that is crucial for the planet.
